Skip to content
WordPress.org

Yorùbá

  • Themes
  • Plugins
  • Àtìlẹ́yìn
  • Nípa
  • Ìwé Ìtónisónà
  • Egbé
  • Kàn síwa
  • Gba WordPress
Wa WordPress jáde
WordPress.org

Plugin Directory

Security-Protection

  • Fi plugin sílẹ̀
  • Àwọn ààyò mi
  • Wọlé
  • Fi plugin sílẹ̀
  • Àwọn ààyò mi
  • Wọlé

Plugin yìí kò tíì ṣe àyẹ̀wò pẹ̀lú àwọn ìtújáde mẹ́ta pàtàkì tó kẹ́yìn ti WordPress. Ó lè jẹ́ pé a kò tọ́jú tàbí ṣe àtìlẹ́yìn fún un mọ́, ó sì lè ní àwọn ọ̀ràn ìbámu nígbà tí a bá lò ó pẹ̀lú àwọn ẹ̀yà WordPress tuntun.

Security-Protection

Láti ọwọ́ webvitaly
Ṣe ìgbàsílẹ̀
  • Àwọn àlàyé
  • Àwọn àgbéyẹ̀wò
  • Ìgbéwọlẹ̀
  • Ìdàgbàsókè
Ìrànlọ́wọ́

Àpèjúwe

  • Security-Protection
  • Donate
  • WordPress plugins

Why humans should prove that they are humans by filling captchas? Lets bots prove that they are not bots with adding javascript to their user-agents!

Security-Protection blocks and stops brute-force attacks.
Want to read more how Security-Protection plugin works?

  • no captcha, because brute-force attacks is not users’ problem
  • no options, because it is great to forget about brute-force attacks completely

Plugin is easy to use: just install it and it just works.

Important: delete ‘admin’ username if you have it on your site. More than 90% of brute-force attacks try to crack the ‘admin’ username.

Few of the most commonly used and worst passwords. Do not use them or similar:

  • 123456
  • p@s$w0rd
  • qwerty
  • qwe123
  • admin123
  • iloveyou
  • letmein

Useful:

  • “Page-list” – show list of pages with shortcodes
  • “Iframe” – embed content
  • WordPress Pro plugins

Ìgbéwọlẹ̀

  1. install and activate the plugin on the Plugins page
  2. enjoy life without login, register and reset-password brute-force attacks

FAQ

Compatible with:

  • WooCommerce

How does Security-Protection plugin work?

The blocking algorithm is based on 2 methods: ‘invisible js-captcha’ and ‘invisible input trap’.
The ‘invisible js-captcha’ method is based on fact that bots does not have javascript on their user-agents.
The ‘invisible input trap’ method is based on fact that almost all the bots will fill inputs with name ’email’ or ‘url’.

How does Security-Protection plugin work in details?

Two extra hidden fields are added to login, register and reset-password forms.
First field is the invisible captcha (copy and paste the code). Second field should be empty.
If the user visits site, than first field is answered automatically with javascript, second field left blank and both fields are hidden by javascript and css and invisible for the user.
If the brute-forcer tries to submit the form, he will make a mistake with answer on first field or tries to submit an empty field and brute-force attack will be automatically rejected.

How does Security-Protection plugin stop brute-force attacks?

If Security-Protection check was not passed than it is brute-force request and the login attempt (or registration, or reset password) is blocked even if username and password are correct.
Plugin sends fake WordPress login cookies to the brute-force bot and redirects it to the admin section to emulate that the password is cracked and many brute-forcers stop their attacks after this.
It is really awesome 🙂

How to test what brute-force attacks are blocked?

You may enable sending info about blocked brute-force attacks to admin email.
Edit security-protection.php file and find “$secprot_send_brute_force_log_to_admin” and make it “true”.

How to stop brute-force attacks if plugins does not help?

If all plugins does not help you to stop brute-force attacks – you can simply rename wp-login.php file (for example ‘wp-login-new.php’) for now and maybe this can help you to reduce load on your site.
And also create empty wp-login.php file for not raising WordPress 404 error because it will start whole WordPress site again during each wp-login.php access.
While wp-login.php renamed – users cannot login, register and reset password.
If you want to have ability to login while you renamed wp-login.php file you should replace all ‘wp-login.php’ strings inside of the wp-login.php file to your new filename (for example ‘wp-login-new.php’).

Àwọn àgbéyẹ̀wò

Kò sí àwọn àgbéyẹ̀wò fún plugin yìí.

Àwọn Olùkópa & Olùgbéejáde

“Security-Protection” jẹ́ ètò ìṣàmúlò orísun ṣíṣí sílẹ̀. Àwọn ènìyàn wọ̀nyí ti ṣe ìkópa sí plugin yìí.

Àwọn Olùkópa
  • webvitaly

Túmọ̀ “Security-Protection” sí èdè rẹ.

Ṣe o nífẹ̀ẹ́ sí ìdàgbàsókè?

Ṣàwárí koodu, ṣàyẹ̀wò ibi ìpamọ́ SVN, tàbí ṣe àgbékalẹ̀ sí àkọsílẹ̀ ìdàgbàsókè nípasẹ̀ RSS.

Àkọsílẹ̀ àwọn àyípadà

2.3

  • Minor updates

2.2

  • added compatibility for WooCommerce
  • code cleanup
  • bugfixing
  • move javascript file to footer
  • added SECURITY_PROTECTION_VERSION constant

2.1

  • masking password in the email log for successful login
  • cleanup code
  • update FAQ

2.0

  • completely rewrote all the code and reorganize the logic of the plugin (now plugin adds two hidden fields – aka ‘invisible js-captcha’)
  • added ‘send_successful_login_log_to_admin’ feature

1.1

  • added sending fake WordPress login cookies to fool the bot

1.0

  • initial release – Protect from login, register and reset-password brute-force attacks using cookie check

Àkójọpọ̀ Meta

  • Ẹ̀yà 2.3
  • Ìgbàgbọ́hùn tó kẹ́yìn ọdún 5 sẹ́yìn
  • Àwọn ìgbéwọlẹ̀ tó ṣiṣẹ́ 400+
  • Ẹ̀yà WordPress 3.0 tàbí ju bẹ́ẹ̀ lọ
  • Dánwò dé 5.5.17
  • Èdè
    English (US)
  • Àwọn àmì
    Brute ForceBruteForceloginregisterregistration
  • Ìwòye Tó Péye

Àwọn ìbò

4.3 lára àwọn ìràwọ̀ 5.
  • 9 5-star reviews àwọn ìràwọ̀ 5 9
  • 0 4-star reviews àwọn ìràwọ̀ 4 0
  • 0 3-star reviews àwọn ìràwọ̀ 3 0
  • 0 2-star reviews àwọn ìràwọ̀ 2 0
  • 2 1-star reviews ìràwọ̀ 1 2

Add my review

See all reviews

Àwọn Olùkópa

  • webvitaly

Ìrànlọ́wọ́

Nǹkan wà tí o fẹ́ sọ? Ṣé o nílò ìrànlọ́wọ́?

Wo àpéjọ ìrànlọ́wọ́

Ṣe ìtọrẹ

Ṣé o fẹ́ ṣe àtìlẹ́yìn fún ìlọsíwájú plugin yìí?

Ṣe ìtọrẹ sí plugin yìí

  • Nípa Wa
  • Iroyin
  • Hosting
  • Privacy
  • Àfihàn
  • Themes
  • Plugins
  • Patterns
  • Kọ ẹkọ
  • Atilẹyin
  • Developers
  • WordPress.tv ↗
  • Kópa
  • Àwọn ìṣẹ̀lẹ̀
  • Ṣètọrẹ ↗
  • Five for the Future
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

Yorùbá

  • Ṣabẹwo sí àkàùntù X (Twitter tẹ́lẹ̀) wa
  • Bẹwo akanti Bluesky wa
  • Lọ sí àkáǹtì Mastodon wa
  • Bẹwo akanti Threads wa
  • Ṣabẹwo si Facebook wa
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Bẹwo akanti TikTok wa
  • Visit our YouTube channel
  • Bẹwo akanti Tumblr wa
Koodu jẹ Ewi.